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We conducted an evaluation of the enterprise-wide security program and practices for the 
Top Secret/Sensitive Compartmented Information systems under the Department of 
Homeland Security's purview. According to the Federal Information Security 
Management Act of 2002 requirements, our review focused on the department's security 
management, implementation, and evaluation aspects of its intelligence activities, 
including the policies, procedures, and system security controls in place for its 
enterprise-wide intelligence systems. In doing so, we primarily assessed the 
department's Plan of Action and Milestones, certification and accreditation, and incident 
reporting processes, as well as its security awareness training. 

The objective of our evaluation was to determine whether the department is adequately 
and effectively protecting Top Secret/Sensitive Compartmented Information and the 
systems that support the Department of Homeland Security's enterprise- wide intelligence 
operations and assets. Our independent evaluation focused on the department's 
information security program for its intelligence systems, at both the department level 
and at the organizational components. The organizational components included in our 
evaluation were the Intelligence and Analysis office and the United States Coast Guard. 

During Fiscal Year 2008, the department has made significant progress in establishing an 
enterprise-wide information security management program for its intelligence systems. 
The department has compiled, updated, and maintained its enterprise-wide inventory of 
Top Secret/Sensitive Compartmented Information systems, as well as those systems that 
support an intelligence mission regardless of the classification. The department's 
enterprise-wide intelligence systems are certified and accredited in accordance with the 
Director of Central Intelligence Directive 6/3. The department has accepted the 
accreditation of the U.S. Coast Guard intelligence system, which was previously certified 
and accredited by the U.S. Navy. 

Some management oversight and operational issues remain regarding the effectiveness of 
the program. In addition, the department still needs to establish and implement a formal 
information systems' security education, training, and awareness program for employees 
with significant responsibilities for the department's intelligence systems. Fieldwork was 
conducted from May through August 2008. (OIG-08-87, August 2008, IT) 
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OIG Hotline 

To report alleged fraud, waste, abuse or mismanagement, or any other kind of 
criminal or noncriminal misconduct relative to department programs or 
operations: 

Call our Hotline at 1-800-323-8603; 
Fax the complaint directly to us at (202) 254-4292; 
Email us at DHSOIGHOTLINE@dhs.gov; or 
Write to us at: 

DHS Office of Inspector General/MAIL STOP 2600, Attention: 
Office of Investigations - Hotline, 245 Murray Drive, SW, Building 
410, Washington, DC 20528. 

The OIG seeks to protect the identity of each writer and caller. 



